Gentoo Archives: gentoo-hardened

From: basile <basile@××××××××××××××.edu>
To: gentoo-hardened@l.g.o
Subject: [gentoo-hardened] Towards better profiles for hardened.
Date: Wed, 13 Jan 2010 16:00:45
Message-Id: 4B4DD396.9060507@opensource.dyc.edu
1 Hi guys,
2
3 I'm emailing because the profile issue came up again in IRC. I'd like
4 to continue the discussion here. Let me try to get it started.
5
6 Here's some general issues with the current profile stucture:
7
8 1) It is horribly complex and difficult to read the inheritance
9 strucutre. Its not clear the inheritance even works. As a result, the
10 user is not sure what is going on. This ambiguity makes it difficult
11 to even start a coherent criticism!
12
13 2) There doesn't appear to be a good structure for seperation of various
14 features. In OO language, I can't choose what to inherit. I wind up
15 getting stuff from other profiles which I don't want and can't control
16 this, so I'm tempted to just USE="-*" and start from scratch, which is
17 not a good thing.
18
19 3) There is a clear bias towards the desktop. If you go that route, you
20 get what you need/want. When you deviate, you start to get more things
21 that you don't want/need and have to struggle against points 1 and 2.
22
23 This effects hardened and hardened+server most. Comments?
24
25 --
26
27 Anthony G. Basile, Ph.D.
28 Chair of Information Technology
29 D'Youville College
30 Buffalo, NY 14201
31 USA
32
33 (716) 829-8197

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-hardened] Towards better profiles for hardened. Shinkan <shinkan@×××××.com>